Fortinet FortiMail Zero-Day Under Active Exploitation, No Patch Available
CISA added CVE-2026-104286 to the Known Exploited Vulnerabilities catalog on October 1, 2026. The flaw is a path traversal and NULL byte neutralization vulnerability in Fortinet FortiMail, rated CVSS 9.8 – critical. Unauthenticated attackers can write arbitrary files to the underlying system via crafted HTTP or HTTPS requests, potentially achieving arbitrary code or command execution (CISA KEV Catalog, October 1, 2026; https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog).
Active exploitation is confirmed. Federal agencies have until October 4, 2026 to perform forensic triage and mitigate. At the time CISA issued the directive, Fortinet had not released patches (SecurityWeek, October 1, 2026; https://www.securityweek.com/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/).
Enterprise email security infrastructure is under attack right now, and the vendor has no fix.
The forensic triage requirement
CISA's directive does not just say "patch." It says federal agencies must perform forensic triage before mitigation. That language means CISA knows attackers are already inside these systems and expects agencies to find evidence of compromise.
Forensic triage before remediation is the order you give when you assume breach, not when you are preventing one. The October 4 deadline is two business days from the KEV listing. That timeline does not allow for careful planning. It allows for emergency response.
Federal agencies are not the only targets. CVE-2026-104286 affects any organization running Fortinet FortiMail — enterprise email gateways used by corporations, healthcare systems, financial institutions, and critical infrastructure operators. The vulnerability is unauthenticated, which means an attacker needs no credentials, no inside access, and no social engineering. They need a crafted HTTP request.
What a CVSS 9.8 unauthenticated RCE means
A path traversal vulnerability lets an attacker write files outside the intended directory structure. A NULL byte neutralization flaw lets them bypass filename filters designed to block that. Combined, CVE-2026-104286 allows an unauthenticated remote attacker to place executable code anywhere on the system and run it.
That is not a theoretical risk. That is root access via the front door, deliverable over the internet, with no authentication required.
Arbitrary code execution on an email gateway means the attacker controls everything that moves through it: inbound email, outbound email, credentials, encryption keys, routing rules, and forwarding configurations. They can exfiltrate mail archives. They can intercept password reset messages. They can inject malicious email that appears to originate from inside the organization. They can pivot to internal systems using credentials extracted from email traffic.
This is not a vulnerability you mitigate with monitoring. This is a vulnerability you patch immediately — except the patch does not exist.
Who answers for this
Fortinet disclosed CVE-2026-104286 knowing active exploitation was underway and knowing they had no fix ready. CISA added it to KEV with a federal deadline and a forensic triage requirement, which means CISA knows attackers are using it right now.
Organizations running FortiMail are exposed. They cannot patch what does not exist. They can take the appliance offline, which eliminates email security entirely, or they can leave it running and accept that an unauthenticated attacker may already be inside.
That is not a choice. That is deciding which failure mode to document.
Fortinet's guidance at disclosure was to monitor for indicators of compromise and wait for patches. Monitoring does not stop an unauthenticated RCE. It tells you the breach happened after the attacker is already executing code on your mail gateway.
Federal agencies have two days to forensically triage systems that may already be compromised and take them offline or isolate them if they find evidence of exploit. Private-sector organizations running FortiMail have no federal directive, no compliance deadline, and the same absent patch. They are making the same decision – offline or exposed – without the forcing function of a KEV listing.
The gap between disclosure and patch
Zero-day means the vendor had zero days to fix it before exploitation began. But CISA does not add a vulnerability to KEV on the day it is discovered. CISA adds it when active, widespread exploitation is confirmed and federal agencies are at immediate risk.
The gap between "we are aware of the issue" and "here is the patch" is the window attackers are exploiting. That gap is not measured in hours. Fortinet disclosed CVE-2026-104286 before patches were available, which means that window is still open as of October 2, 2026.
Every organization running FortiMail during that window is making a bet: either the attackers have not targeted us yet, or they have and we have not detected it. Neither outcome justifies the exposure, and only one of them is true.
What happens next
Fortinet will release patches. CISA will update the KEV entry with remediation details. Federal agencies will either confirm clean systems or document compromise and begin incident response. Private-sector FortiMail operators will decide whether to follow CISA's lead or wait until their own monitoring flags suspicious activity.
The vulnerability will remain CVSS 9.8. The exploitation will remain confirmed. And the organizations that waited for a patch that was not ready before taking their email gateways offline will remain exposed for however many days Fortinet needs to ship the fix.
CVE-2026-104286 is not sophisticated. It is a path traversal flaw combined with a filter bypass, executed over HTTP, requiring no authentication. It is the kind of vulnerability that should have been caught in code review, flagged in static analysis, and patched before release.
It was not. Now it is a KEV-listed, actively exploited, unauthenticated RCE with no available fix and a federal forensic triage deadline 48 hours out.
This is what happens when enterprise security infrastructure ships with critical flaws and vendors disclose them before patches exist. Organizations are left choosing between operational continuity and exposure to an attack that is already happening.
CISA's October 4 deadline will pass. The question is how many FortiMail appliances are still running when it does, and how many of them are already compromised.